The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Climbing Mount CMMC
Climbing Mount CMMC artwork

What Every MSP Needs to Know About CMMC (feat. Matt Travis, CEO of Cyber AB)

Climbing Mount CMMC · 2026-06-25 · 49 min

0:00--:--

Key moments - from our scoring

Substance score

59 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality9 / 20
Guest Caliber16 / 20
Specificity & Evidence13 / 20
Conversational Craft10 / 20

Matt Travis, CEO of Cyber AB (the independent nonprofit accreditation body for CMMC), discusses the state of the Defense Industrial Base's cybersecurity compliance ecosystem with MSP hosts Kayleigh Floyd and Bobby Guerra. The conversation covers Cyber AB's role - ensuring competency, consistency, and impartiality across 105 active C3PAOs conducting Level 2 assessments - and the organization's financial survival through the three-year rulemaking pause under the Biden administration, when Registered Practitioner and RPO programs kept operations afloat. Travis addresses the scale challenge: the DoD estimates 163,000+ small businesses in the DIB requiring CMMC certification, though the actual number may be significantly higher given subcontracting flow-downs under FAR clauses 252.204-7012. He explains the department's "levers and dials" approach - adjustable Level 2 requirements and waiver authority - to balance warfighter needs with ecosystem capacity. MSPs operating in this space need clarity on how DoD will manage implementation timelines, C3PAO availability windows (currently booking through November), and whether the market can scale sufficiently to meet demand without driving smaller contractors out of the DIB.

Key takeaways

  • →The Cyber AB is an independent 501(c)3 nonprofit, not part of the Department of Defense, focused on ensuring competent, consistent, and impartial CMMC Level 2 assessments across all C3POs.
  • →The organization survived early financial hardship through the RP and RPO practitioner programs while federal rulemaking paused for three and a half years, and is now hiring aggressively as operations scale.
  • →An estimated 163,000+ small businesses and subcontractors in the DIB will need CMMC certification, a number likely undercounted due to multi-tiered subcontractor flow-downs that could double the actual scope.
  • →The DoD has built adjustable requirements including self-assessment options and potential waivers to manage ecosystem scaling, balancing security needs against the risk of driving companies out of the defense industrial base.
  • →Currently there is no significant backlog for C3PO assessments with 105 active in the marketplace, though availability varies by region and some are booked through November.

In this episode

  1. 1Introduction to Cyber AB and CMMC Certification
  2. 2Cyber AB Structure: Non-Profit vs Government Organization
  3. 3Three Pillars of Cyber AB Operations: Competency, Consistency, and Impartiality
  4. 4Financial Challenges During CMMC Rulemaking Pause
  5. 5Practitioner Programs and Revenue Survival
  6. 6Current Ecosystem Growth and Hiring Trajectory
  7. 7DIB Small Business Landscape and Scaling Challenges
  8. 8Estimated Entity Numbers and Implementation Strategy

Mentioned

Cyber ABAxiomMatt TravisKayleigh FloydBobbi GuerraDepartment of DefenseNIST 800171C3PAOCCPCMMCLockheed MartinBoeing

Guests

Matt Travis

Topics in this episode

CUI (Controlled Unclassified Information)CMMC Level 2DibCACCyber ABC3PAO (Certified Third-Party Assessor Organizations)CCP (Certified CMMC Professional)32 CFR final ruleNIST 800171 Revision 2DIB (Defense Industrial Base)Practitioner Programs (RP/RPO)Defense Contract Management AgencyC3PO (Certified Third Party Organizations)CCP (Certified Compliance Professional)CCA (Certified CMMC Assessor)NIST 800-171 Rev 2RP and RPO (Practitioner Program)

Questions this episode answers

Is Cyber AB part of the Department of Defense?

No, Cyber AB is an independent 501(c)(3) nonprofit formed in late 2019 at the DoD's encouragement, not as a government entity. It operates on no government contract funding and generates revenue from fees tied to CMMC ecosystem activity.

What are the three core pillars that Cyber AB ensures in CMMC Level 2 assessments?

Competency (assessors are properly certified), consistency (small businesses in Texas receive the same procedural standards as Lockheed Martin or Boeing), and impartiality (no conflicts of interest, insider advantage, or corner-cutting).

How did Cyber AB survive financially during the three-year CMMC rulemaking pause?

The Registered Practitioner (RP) and RPO programs kept the lights on while Level 2 assessments were halted, as defense contractors continued preparing for eventual compliance by pursuing training and consulting services.

How many small businesses in the Defense Industrial Base need CMMC Level 1, 2, or 3 certification?

The DoD estimates approximately 163,000 small businesses, though the actual number is likely higher when accounting for subcontracting flow-downs under FAR clauses like 252.204-7012, which can extend CMMC requirements through multiple tiers of suppliers.

Are there currently bottlenecks in scheduling C3PAO Level 2 assessments?

As of the interview, no systemic bottleneck exists; 105 C3PAOs are active and companies can schedule assessments (some booked through November, others with availability), though capacity varies by region and timing.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode contains genuine operational insights - distinguishing MSPs who prepare OSCs from MSPs who run networks, the bogus certificate discovery, and the forthcoming CMMC Body of Knowledge - but these are diluted by significant conversational filler, mutual validation, and repetitive throat-clearing that inflates the runtime substantially.

I always look at are there enough people to help companies prepare for cmmc? I feel pretty good about that. Are there enough companies to help defense contractors run their networks and actually maintain requirements to the standard? That's a different question.
We came across just last week, uh, a bogus level 2 certificate that a non C3PO generated, taking a valid UID from another C3PO and some poor DIB company was uh, snookered into.

Originality

9 / 20

The observation that NIST 800-171 never mentions 'managed service provider' is a pointed and underappreciated structural critique, but most of the content follows the predictable CMMC ecosystem narrative - scaling concerns, financial survival during rulemaking, and credential program transitions - that circulates widely in this community.

It always struck me that you could read NIST 800171 and never see the term managed service provider. You don't see that in any of the DoD assessment guides scoping guys. It wasn't until we saw 32 CVR where we got the external service provider.
I think CMMC has been catching up to that realization that you can't solve the problem of protecting CUI if you're not fully and coherently incorporating the role of the msp.

Guest Caliber

16 / 20

Matt Travis is the sitting CEO of the Cyber AB - the actual accreditation body for CMMC - and shares genuine internal intelligence including the organization's financial history, active hiring plans, a live enforcement case, and pending policy developments; this is a primary-source practitioner, not a thought-leader proxy.

I just hired a chief operating officer. We've just made an um, offer out to a compliance officer whose full time job will be to police the ecosystem
the Cyber B has never received a dollar of contract, uh, money, of taxpayer money, any, no government revenue at all. We generate our operating revenue from the fees that are attached to some of the economic activity that goes on in cmnc.

Specificity & Evidence

13 / 20

The episode references specific regulatory tables by page number (32 CFR page 83176-83177), cites 105 active C3PAOs, 410 RPOs, year-by-year certification volume projections (382/1,900/6,000/12,000), and approximately 40 certified MSPs/ESPs - providing a real quantitative skeleton, though some claims rely on informal estimates and acknowledged uncertainty.

we've got C3POs over you know 105 active in the marketplace
we have a 410 registered practitioner organizations. Uh, you know we're training's outdated, the quality varies among those greatly.

Conversational Craft

10 / 20

The hosts ask genuinely practitioner-informed questions - the MFA inconsistency example (Hello for Business vs. Duo) and the enforcement 'wanted posters' pivot show real domain knowledge - but they overwhelmingly validate and agree with the guest rather than pushing on ambiguities, and several questions are broad scene-setting rather than targeted probes.

What wanted posters have you put up?
Some organizations feel that hello for Business, you know, doing the little pin with hello for Business is acceptable for mfa. Some assessors feel that way. Some assessors are like heck to the no, that's not acceptable either.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B56%
  • Speaker C28%
  • Speaker A15%

Most-used words

cmmc38level29msps28help26program22cyber20small18ecosystem17requirements17bobby15organizations15accreditation14space14part13start13department13

Episode notes

In this special episode of Climbing Mount CMMC, Bobby and Kaleigh discuss the intricacies of the CMMC ecosystem with Matt Travis, CEO of the Cyber AB. They explore the challenges, opportunities, and future strategies for MSPs, assessors, and small businesses navigating cybersecurity compliance. 32 CFR Final Rule : 2024-22905.pdf Cyber AB Website : CyberAB > Home Time Stamps: 00:00-02:14 Introduction 02:15-04:03 What Is the Cyber AB? 04:04-09:27 Surviving the Early CMMC Years 09:28-12:26 CMMC Momentum Is Growing 12:27-16:13 Can the Ecosystem Scale? 16:14-21:47 How the DoD Will Manage Rollout Challenges 21:48-27:50 The MSP Capacity Problem 27:51-33:24 Why MSPs Are Essential to CMMC 33:25-35:43 New Support for MSPs & Contractors 35:44-39:54 Creating a CMMC Body of Knowledge 39:55-44:00 Policing the Ecosystem & Preventing Abuse 44:01-47:40 The Future of CAICO Under ISACA 47:41-49:29 Conclusion Website: YouTube: Axiom's LinkedIn: Bobby's LinkedIn: Kaleigh's LinkedIn:

Full transcript

49 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hello, climbers, and welcome to Climbing Mount Seamum. Back to the five, six. Good job. What is it doing?

Speaker B: Look.

Speaker A: Sc. Hello climbers, and welcome back to another episode of Climbing Mount cmmc, the podcast. My name is Kayleigh Floyd and this is Bobbi Guerra and we are your hosts of climbing Mount CMMC. We're part of an MSP called Axiom that CMMC Level 2 certified and trying to figure out how to do this whole thing not only for ourselves, but for our clients that need it. And if you're along for the ride, we're welcome to have you. But also we have a special guest, very special guest on today. For those of you who live under a rock and don't know what, the Cyber AB is accreditation body for cmmc. And we are excited to have Matt Travis on. He's the CEO of the Cyber ab. Matt, thank you so much for taking the time and joining us today.

Speaker B: Kaylee, thank you for. The invitation is probably long overdue given the success of the podcast. And that's on my end, so I'm glad we're able to connect.

Speaker A: No, we're thrilled to have you. I mean, we saw you at, what was it, CMMC Midwest this year in 2026, and we were like, you know, what if you're free, if you just happen to have about 45 minutes, what if you talk to us about some things and honestly, Bobby's going to take it over. But I, I did want to say that our goal today is kind of to get a different perspective on. I know that Matt talks about the ecosystem as a whole, as well as where the Cyber AV is involved, which is very important. But we have a little tiny group over here called MSPs, you know, that are under the label of external service providers in cmmc. And there's just some really interesting things happening in the ecosystem. Obviously, it's still in the infancy of it all, and we're figuring this thing out. January of 2025 is when CMMC, um, level two assessments were allowed to start happening and occurring with C3 PAOs. And it's been really crazy to go through this journey as an msp going through multiple different client assessments and whatnot. And we're just really excited to dive into certain aspects about this today. So, yeah, I'm thrilled. Bobby, I'll let you take it over because I know you're eager to steer this.

Speaker C: Yeah, Matt, let's kind of let you start off because I'm going to be honest here. Like, when I first was getting into the system, I thought that the Cyber AB was part of the Department of Defense. So can you like maybe sort of very quickly talk perhaps the inception of the Cyber AB and the difference and then where you guys are in the space just to kind of level set for people, because not everybody may not really know that.

Speaker B: Right, Absolutely. And in doing so, I'll start off by just reminding everyone, as you point out, we are not part of the Department of Defense. We are a, uh, non profit, independent 501c3 charitable organization. And so on that note, nothing that I say should be construed as representing anything, any policy or positions of the pentagon or the U.S. government. Uh, but we were essentially formed at the encouragement of the department back in late 2019 when the CMMC initiative was first kind of announced. The department, uh, wanted an accreditation body to be really dedicated just for this program. There are other accreditation bodies out there in the United States. We kind of do it differently. Not surprisingly, our accreditation bodies are largely in the private sector, whereas around the world, usually the accreditation bodies are within the government itself. Given all the things that the department wanted the CMMC accreditation body to do, not just to credit, but to kind of build an ecosystem, administer it, police it, run a marketplace, uh, the existing accreditation bodies recognized, well, that's not really what we do. And so the AB is really formed by an original board of directors who volunteered. They came from the defense sector, from the cybersecurity, from cmmi, uh, and really formed the organization. But from the onset, it was always intended and designed not to be part of the Pentagon, but to be an independent nonprofit.

Speaker C: Uh, um, given that perspective, what are some challenges you think that you see, you're glad are in your revered mirror.

Speaker B: Right.

Speaker C: And what are some that you see before you?

Speaker B: Well, I think if we're honest with ourselves, that those early board of directors before, you know, I showed up, I'm not sure they all understood what an accreditation body does because they came from the defense sector or the cyber sector or the audit community. And uh, you know, we at our core exist, really do three things as it relates to CMMC to ensure that every level two certification assessment is done competently, that the C3POs know what they're doing. They're using certified assessors and CCPs that are, that have been certified by the CACO, that they're, they are conducting these assessments consistently, that they're following similar procedures, and that if you're a small business in Texas, that you are getting essentially the same type of assessment procedurally as well as the rules that, uh, Lockheed Martin or Boeing would be getting somewhere else in the country. And then perhaps most importantly, that these certification assessments are done impartially, that there is no inside game, there's no cutting corners, any conflicts of interest, uh, are disclosed, identified and either mitigated or avoided depending on the nature of those. And those are really the three pillars, competency, consistency and impartiality. So make everyone aware what we do is an initial challenge, right? Because we can't help train and we can't help give tax credits or grants to small businesses who are trying to conform to this UMC standard. So I think understanding what we were chartered to do as a first challenge and then I think early on in the ABC's history we didn't appreciate the role that we played and so kind of policing ourselves, making sure that when we're speaking in public that we're not endorsing products or services, that we ourselves are being impartial, that we're disclosing things. So there was uh, you know, one of the challenges we had is that the contract with the Pentagon is a no cost contract. And so the Cyber B has never received a dollar of contract, uh, money, of taxpayer money, any, no government revenue at all. We generate our operating revenue from the fees that are attached to some of the economic activity that goes on in cmnc. And since, as you both know very well, there were a lot of fits and starts to the program early on after the AB was formed, when essentially in April of 2021 when the new Biden administration came in, they decided to hit pause to take a six month strategic review at cmmc. Hm. And that really killed all of the burgeoning activity that was starting. So we had a tough time navigating uh, our own resilience and existence. There wasn't much going on.

Speaker C: I'm glad you brought that up because that's been something that's always been, I don't know, maybe a inquiring mind kind of want to know about that is I'm a provisional instructor trying to get my CCI filled out the forms and we'll see how that goes. But the, the um, when we go to teach the material, one of the things that I always explain is that the Cyber AB as it was starting off, as it was making revenue, I guess predominantly from the RP and RPO programs initially because assessments were really happening. And so it was since you're not getting any money from the government, I mean most organizations, because the DIB is so large, they just assume the Cyber AB is this Massive organization that had tons and tons of members. I'm like, actually no, it's actually very small. And here's sort of the reason why. How tough was it financially for you guys starting off in that during that timeframe?

Speaker B: Yeah, there were some tough times. Some using um, naval analogies, there were some rough seas or whatever metaphor you want to use. And it was, I think the biggest reckoning was when we knew that the changes the Biden administration wanted to make to the program were going to result in another round of rulemaking. But when we learned how long rulemaking was going to take, initially we thought it would be a year and then it was clear it was going to take three years and it ended up being about three and a half years. That was when we had to really figure out how we're going to survive. And you know, we obviously been operating on the skeleton staff up until recently and so keeping that team intact and finding ways. And you were absolutely right Bobby. It was the practitioner program, the RPS and RPOs that kept the lights on because they knew that there was still, they were the main one that could actually work. Right. Because there were defense contractors who were paying attention, recognizing uh, that okay, even though this thing is pause and go through rulemaking. I've heard enough of the defense officials talk about this. I've seen the requirements in the NDAA on Capitol Hill. So I know this is this or something like this is going to have to happen. The NIST 800171 Rev 2 is the standard. I might as well start getting ready. And so some of the RPs actually and some of the candidacy through POS kind of turned to consulting uh, because they too are, you know, a challenge. And how can they, you know, if they invest in becoming part of this EMMC program, how are they going to withstand and endure this long protracted rulemaking process? And then on the instructor side and you can you live this right. The classes weren't being filled because if you're a uh, CCA candidate, it's a non trivial investment to pay for the CCP course and then pay for the exam. And all the time you go into studying for it and then you gotta do the same thing at the CCA level and then you can't monetize that credential because you. Other than some. We had some joint surveillance program with didcac. We did some pilot stuff to try to get people some experience. Long winded way of saying those uh, were some heady ties. I'm glad they're behind us. But yeah it made.

Speaker C: Are you seeing a good trend now? Are you guys happy with uh, the trajectory financially? Because obviously the cyber AB is critical to the infrastructure. Are you guys happy with uh, this?

Speaker B: We are hiring now I just hired a chief operating officer. We've just made an um, offer out to a compliance officer whose full time job will be to police the ecosystem as well as doing some of our own internal compliance requirements. Uh, we'll be hiring a uh communications special. We don't communicate very well whether it's our website, social media. There's a lot of improvement to be done there. So now that, now that the operations of CMMC are underway we've got C3POs over you know 105 active in the marketplace uh for everything I'm hearing and from them what they talk to us on a weekly basis. They are busy. Um, and even though you know that levels level 2 requirements aren't yet requirements the department certainly reserved the right to start putting some of those in contracts and we're seeing that. But even without that, just the fact that the rulemaking is over um, I think spurred a lot of activity. So I am pleased we're seeing a good uptick uh across all parts of the ecosystem and I suspect that that will continue.

Speaker C: Yeah, we, we grew 70% last year. I mean it has just been a hockey stick like you know but you know I got my CCP 2022. The test hadn't even come out yet, you know so you know everybody I think that started CMMC in, in the early days like they have their kind of, you know I went uphill in a snowstorm both ways to they talk about just because it's such a burgeoning uh industry and it still is, you know it's still finding its sea legs in a lot of areas. Uh but a lot of positive signs, a lot of um, things that are indicating that we are trending in the right way. Let's talk a little bit about the ecosystem as it's starting to um, continue on its transition. In 32 CFR they have several tables and I want to highlight uh one of them. I'll share in just a second. But it sort of talks about in the S and P space and managed service providers provide like typically that's our focus. Most MSPs are focusing in the MSP space and I don't know, maybe you might agree with this percentage but it seems like small businesses account for like 70% of the DIB space. Would you. Is that, does that Sound reasonable to you? It seems like that way with the numbers that I'm seeing here as well.

Speaker B: But you know, informally over the years, those are the kind of numbers you always hear that uh, you know, 85% of the nation's critical infrastructure resides in the private sector and about 70% the DIB is small and medium sized business. But I don't have any empirical data other than kind of what some of the NDIAs and other trade associations publish. But clearly having been a defense contractor of my own, a small business, uh, I think that sounds right given most of the companies you interact with are small and then some of all of you eventually are working for larger primes. But it's a huge part of the dib. And I think when you talk about cmim, I'm sure we'll get to it. Some of the challenges of the program is making sure we're not chasing out uh, those small companies who find the requirements or the cost of the requirements, uh, too much to handle.

Speaker C: Yeah. So let me share the screen here. So this Table 5 in the 32 CFR final rule in here, it has the estimated number of entities by type. And this table five that we have, which uh, I guess is on page 83176.

Speaker B: That's great.

Speaker C: But in this one it talks about the uh, small businesses and other than small businesses, it's saying in this, their estimate is 163,000, almost 164,000 organizations they're considering in the small. They're going to have to either get level one, level two, level three.

Speaker B: Right.

Speaker C: What's the challenge with that number and how accurate do we feel that that is?

Speaker B: You know, certainly the Pentagon through all of its Defense Contract Management Agency. And I think a lot of those numbers came from contracts. Right. I think they weren't taking a roll call of companies, but rather looking at all the contracts and the known or estimated number of subcontractors supporting those contracts. And so I frankly think the number is probably larger than what you see there. Um, and of course at the AV, we're really looking just at level two certification, not to dismiss level one or level three. And so that total, you know, 76 and change. Generally we talk about level two C3PO assessments, you know, 80 to 110 is kind of the range that I hear about. Regardless, it's a big number as you rightfully point out. And so obviously one of the questions we get asked all the time is, uh, can ecosystem scale to the sufficient level to meet the demand signal of that level two Certification assessment. And I'm confident when we get to the end of the three year implementation period, we will be there or close to being there. But there's still a lot of variables on that. Right? One that there's no dramatic changes to the program or if any changes that would encourage more participation of assessors and instructors and C3PO is not fewer. And that you know, the economic factors and you know, the world events drive a lot sometimes of how many companies are in the dib. But I think as just a starting point in terms of understanding the community that needs to be served by the CMMC ecosystem, you know, that that's certainly a big number, but one that I think what's nice about the way CMMC was designed, I mean if you were to tell me that a bunch of government inspectors out to service them, well then that's a huge lift of trying to. But there's an economic incentive for C3POs and individual assessors to be part of CMMC. Right. This is the whole, the whole premise of the program was to take advantage of those supply and demand dynamics and that there's a very strong demand signal there. And uh, we expect the private sector to respond by providing sufficient supply over the course of the next three years.

Speaker C: Yeah, and I want to focus in more on that. You're bringing up so many good points. I really want to talk about this because I don't feel like we've had uh, sometimes as many pointed conversations around this. One of the challenges that we have with that number correct, uh, me if I'm wrong is that it's traditionally looked at from the DoD's perspective of the primes and not necessarily all the subs that are going to be down there. Because a lot of these contracts could have multiples of subs, of subs, of subs, of subs. And as 30, you know, as 170, uh, as 2522 or 47012 has those flow downs go all the way down. It's flow down all the way baby. There's no limit to how far it go, uh, so it can keep flowing that down and those all would then be subjected to the contractual. I mean I would think it would be reasonable to assume that number could easily be double, uh, that you could see when you have like the smaller sub organizations that are maybe 10, uh, 20, um, that are just doing parts and pieces of things. No one knows for sure exactly what that number is going to be, but it's going to be definitely, in my opinion, larger than the 163,000 that it has listed there.

Speaker B: And I think, Bobby, that's why you see the department bifurcated Level two, because, um, not speaking for them, but my interpretation of that is they wanted a couple dials that they could adjust depending on how quickly and how well the ecosystem was scaling. So as we get into Level two, entering into contracts, if there's a sense that there's a backlog and a lot of level 2 companies are having to wait 6 to 9 months to get a C3PO availability, well then they can put more self assessment requirements in contracts. Right. So they're not going to be flooding the procurement lanes with Level 2 C3PO requirements if they know that there's a, you know, there's a bit of a bow wave of, uh, backlog. So I think that's one tool that the department has now is GAA reported out. Well, if the whole goal is to get Level two, you know, certified, that doesn't necessarily help in terms of protecting cui. But I think we all recognize that this is a very ambitious conformity assessment initiative. And I credit certainly the PMO and the DIBCAC recognizing that this can't be done overnight. We have an implementation plan that's going to be three years in the making. We all need to be patient. We need to make sure that we're keeping track of the growth. And if all of a sudden find ourselves off pace, then we'll need to revisit how we incentivize better, more participation for assessors and, uh, C3POs. But I'm feeling okay where we are right now, but. But, uh, every month, every week, frankly. But we're looking at those numbers very closely in terms of how we're scaling.

Speaker C: Yeah, I'm so glad you brought that up because it really does kind of talk about how the system's ramping up. And I don't know if I feel like I've gotten a good piece in how those levers and dials are going to be used effectively come November as we go into the second phase of that approach, which the way it could be interpreted is it could be more aggressive or it could be, like you were saying, more, uh, realistic to. I mean, because it comes down to, you know, you're going to need missiles and tubes, right? You're going to need technology in the sky, you're going to need jets flying and doing things and compliance is great, but if you don't have those things, we're kind of screwed. So there's a balance there that has to Happen. And I just don't know if I feel like I've gotten clarity about

Speaker B: what

Speaker C: is their strategy and how aggressive are they going to be about keeping their finger on the pulse around that. Have they given you guys any indication about that?

Speaker B: No, and I wouldn't expect them to at this point. I mean, one of the aspects of our great democracy is that sometimes we have new administrations come m in every four years. And so when that happens, you get new leadership that wants to take stock of programs, whether it's CMMC or something else, and then figure out, okay, how do we improve it, how do we adjust it or otherwise. And Certainly the new CIO, uh, Ms. Davey, who was sworn in just before Christmas and is still kind of assessing her portfolio, I, uh, know, has been obviously getting briefings from the PMO about scale. And that balance that you talked about, uh, Bobby, is that the priority is making sure the warfighters have what they need and that the information and the CUI that went into building the tools and the systems and the services that, that enable their success are protected. And it's that constant, you know, it's that balance. There's always a balance between, you know, security and productivity or efficiency. And I think current leadership is looking at what's the right balance because if, if all the CUI is protected and, but we're driving companies out of the dib because either it's too expensive or they can't, they can't get in line to get, uh, a C3PO assessment, they decide, heck with it's all going to build widgets for somebody else. That's not great. But the opposite is not great either that if we're not protecting cui, those war fighters are potentially using compromised systems where adversaries either have reverse engineered it to fight against us, have uh, sabotaged it, or developing countermeasures based on that CUI that they have exfiltrated. So it's a balance and I think another tool in the toolbox, again, not to speak for the department. There are waivers. Right. And so if it turns out that, you know, we just don't have the ecosystem scale where we'd like it to, you know, certainly the department has reserved the right, at their discretion, to waive requirements, and I have no insight into how or when that would be used. I just know that the department has anticipated they're going to have to see what, you know, see how this evolves and what speed it is evolving. And that'll drive some of the decisions they make, I suspect.

Speaker C: Yeah. And I think that would provide such, I think, more calm and peace about how things are going to be as we slide into November and the beginning of next year, how that's going to go.

Speaker A: Bobby loves calm and peace. But again, remember, we came from the MSP space. We are not familiar with how the DoD runs always. And I think, I think that, I think that Bobby wants a handwritten letter.

Speaker C: That would be great. Certified would be great.

Speaker B: They're all legitimate questions, Kaylee. And the thing when, um, others like, you know, have asked me questions like Bobby is. And sometimes my response is, well, right now, is there any trouble in getting a C3PO assessment on the books? And there's not. Right. 105. Now, some stance cards are booked well until Thanksgiving, others are not. So if you're a company right now that says, hey, I want to get Level 2 certified at the end of June, you can do that. Now, when we get to the point where I can't say that that's when I start, I'll be getting more nervous about are we scaling at the right rate or the necessary rate. But until now, it's certainly a legitimate question to ask, but. But it's not a problem right now.

Speaker A: I think that Bobby's probably going to talk about this next. But we kind of challenged you with this question about the bottleneck of, uh, potentially right now. And so, you know, we've heard a lot of people have different perspectives on what they see a potential bottleneck for the ecosystem being right now. And I know you've talked about multiple times, um, it's wonderful the amount of CCAs that are out there, but we always need more of those, you know, and lead CCAs that to step up to the plate and DO assessments with C3PAOs and be able to do that. And we, I know we talked about this when we were preparing for, for the podcast episode, but something that we're challenged with is, you know, implementers like us, um, how many of we, we look around and we're like, how many of us are there? Right? How many people are also doing this? I know we have a few names that people are familiar with, like Summit 7, Sentinel Blue, um, you know, MNS Group, we have some friends out there that we talk to, but we're wondering like, ok, many of us are there and how many companies can they get through to help the ecosystem prepare? So, Bobby, I know you were going to talk about that too.

Speaker C: Yeah, let's, let's. I'm going to share the screen again to make sure on the final Rule it's, it's page 83177. Um, and in here, this, this table denotes the number of entities in this period. Are, are for the small entities.

Speaker A: The very top one. And table six is small entities.

Speaker C: Small entities.

Speaker A: Right.

Speaker C: So, so if we look at this level two certifications in the first year they're estimating about 382. And then uh, in year two in the phase two is 19, uh, hundred and then year three is 6,000 and then year four is 12,000. And it just sort of planes out at the 12K mark that we see that they're thinking. But one of the things that I've just kind of looked at, Matt, and I just want to mention to you and get your perspective on it is um, when you look at the MSP Collective, right, that tracks level two certified MSPs like us, I think that would be the first gauge of organizations that have the best chance of understanding what it takes to get an organization ready. And there's about. I went through and counted it before the podcast. I think it's just at 40. So they have about 40 people.

Speaker A: External service providers, to be clear. So not all external service providers are managed service providers. Right. It includes a couple different types of companies.

Speaker C: Yeah. Like in that list that they have, uh, some might just be MSSPs, where they're just doing the tech, like the security piece of SIM monitoring and other components. So not all of those 40 are going to be like, hey, if you come to me, I can take you from start to finish and solve all of your woes when it comes to CMMC. So let's just say that those 40 are there and let's just double it. So now we have like 80 uh, of other people out in the space that are involved in it. What I'm finding is, as I've had conversations with the other MSPs, around 10 to 20 is what they can handle in a year because they're just, they're smaller right now. We're starting to ramp up now. Summit did like what, a hundred? They're coming up on 200. I mean not everybody scales like that, but when you look at that and you think to yourself, let's just do it on the low end, you know, so let's say 80. That's only 800 organizations roughly that you can start moving through if they, if they come. Because I think there's a lot of organizations right now. This is just my opinion. I really want to get your opinion about this too. Um, I think as we were coming into the launch of cmmc there was a lot of companies that have been like let's go, let's go, let's go. And then we flush those out. And now it's the organizations that are sort of playing chicken trying to determine when they want to go for it or not. But then it comes down to I still think even if everybody that wanted to start to move through, I feel like there's enough C3PO and CCAs that could handle a lot of that. I think the biggest problem is going to be companies like, like us that are going to be people that help them get implemented. Because if you think about it, 70% of the organizations are SMBs are going to need people like us. I just don't know if there's enough of us to get it done. And if you look at just very, very lazy math Here, you know, 800 is not going to get you where you need to be. Assuming that the MSPs are the ones that are in town doing it and that's not the case. We obviously know that's not. There's RPOs and other people that are doing it that would not fall under that category that could help pour into filling that gap. But still you can see that gap could be pretty significant. Um, that can start to happen of implementers of these organizations. What do you think about that?

Speaker B: Well, you kind of touched on a distinction that I make which is there are implementers to help OSCs meet the standard and prepare for their certification assessment and then there are entities like yours that actually helps OSCs run their networks. And so for you, and you mentioned the RPOs, we have a 410 registered practitioner organizations. Uh, you know we're training's outdated, the quality varies among those greatly. That's a problem that we uh, fortunately been well aware of and now with resources are starting to do something about it. But they exist because what the department asked us to do with the RPO program was we don't want especially small businesses in the DIB to be susceptible to stake oil salesmen who don't know anything about cmmc, offer to help them and then don't know what they're talking about. So, so all the RPOs, we do a background check, they have to have at least one person take some modest training, pass a modest exam and ostensibly they are following the program, attending the town halls and all of that, but not all of them are MSPs. So I think in terms of is there enough help out there to help you understand what the requirements are and to start implementing. I think there's again, we have 400 companies that could help do that. But I don't think the department recognized how many companies within the DIB rely on MSPs to run their networks. It's going to be very few that have their own tech stack that they manage themselves. And I think, I know we'll get into this, but the MSP function was something that I think was very much under appreciated, underestimated as uh, CMMC was being formed. It always struck me that you could read NIST 800171 and never see the term managed service provider. You don't see that in any of the DoD assessment guides scoping guys. It wasn't until we saw 32 CVR where we got the external service provider. Uh, we can talk about whether, you know, how helpful that is or not, but it is one of those. And I think some of it was just how quickly technology evolved in the economic model where MSPs were relied upon overwhelmingly for a lot of companies even outside the jet. When I was at cisa, uh, we saw MSP being the targets of cyber threat actors. I mean the MSPs were the primary target because of what they do and the data that they had access to. And so I think CMMC has been catching up to that realization that you can't solve the problem of protecting CUI if you're not fully and coherently incorporating the role of the msp. And then to your point, Bobby, is the volume of MSPs there to support those numbers that you cited in terms of who are going to need implementation or sustainment help to maintain their networks? And again, I would come back to i1 is great opportunity for MSPs and I would hope that that would encourage more businesses to get into this sector. It surprises me. We saw a pretty prominent MSP kind of incur some trouble here a couple weeks ago and ended up kind of liquidating and being sold off to two different other companies. So I haven't done the forensics there, but I would think it's a pretty rich market for MSPs. That doesn't mean that the uh, demand signal will be satisfied. But I always look at are there enough people to help companies prepare for cmmc? I feel pretty good about that. Are there enough companies to help defense contractors run their networks and actually maintain requirements to the standard? That's a different question.

Speaker A: Right. I was thinking about this too. I'm um, glad that you brought up RPOs of helping people get ready too because I feel like there's a different type of, there's a different type of getting ready for CMMC that MSP that a managed service provider has to do. I might be a bit biased on that because that's where we came from. And the tool stack that's included the way that we service our clients. There's so many intricate spider webs that are intertwined that even if you get, let's say, which I talk to many contractors, small businesses on a day to day basis that have, have you know, an MSP that, that is not in the CMMC space but is willing to help them out and they try to bring somebody in, let's say like an RP or RPO company and there, you know, those types of organizations still, even, even with the help that they can provide for CMMC basis, there's a different type of level of understanding that needs to happen for that msp. You know, it's, it's, it's talking a different language that not all RPOs can do, you know, because it is more technical and things that are intertwined. And then, you know, you layer on top of that a lot of the conversations I have with C3PAOs. The, the problem that they have in phase one is the MSP. The MSP is not ready. And so, you know, you hear those two things and you're like, okay. So it sounds like though that you know, that the clients or the, the contractors that are wanting this level two are getting ready but then they're having to drag sometimes their MSP behind them if they don't know what to do, you know. And so you're seeing this weird like, like seesaw effect of like we're trying to lift them up, but then here comes the boulder of the MSP bringing them down, you know.

Speaker B: Well, Kaylee, that's a great point that I think some MSPs M, who may not be as tied into the DIB, maybe have 10 or 20% of their clientele in the, in the sector, when they realize what's required of them, they'd want to be dragged into it. They're like, wait a minute, I don't know if I'm signing up for all this. And that leaves those defense contractors in the lurch. And to Bobby's point, maybe there are actually fewer MSPs available because not all those MSPs necessarily have kind of embraced, you know, their role. The CMMC program.

Speaker A: Yes.

Speaker C: Yeah, we, I, I just did very, very rough math. So no one come at me at the accuracy because I'm very out in the open with the inaccuracy of what I'm about to say.

Speaker A: So.

Speaker C: But I would estimate that we're going to need a few thousand MSPs to step in the space and really understand it. And right now 80 ain't anywhere close to that. That's not great, uh, English, but you know.

Speaker A: 88.

Speaker C: Yeah, yeah, 88. You know, uh, it's like we are. If it is true that MSPs are that critical to the S and P market, and I think it is in my heart, I feel like it really is. I think we MSPs play a critical role in the MSP space, in the DIP space, and a lot of that's being filled with, uh, msps. We get contacted daily by companies that are like, hey, our MSP just doesn't get it.

Speaker B: It.

Speaker C: What are some things that the Cyber AB can do to help around that? To try to help? Because I get contacted all the time, hey, Bobby, how are you guys doing this? You know, and it's like, I can't just stop what I'm doing to like, okay, I'm going to have a, you know, six hour confab with this company and then the same thing again with this other company. That's part of the reason why we have this podcast is to try to get the word out to try to help, say, hey, we need you as an msp. But you know, I, you know, I can't. And just a few of the other MSPs that have really started to focus on this is their goal, they can't do it. But does the Cyber AB have some offerings that can help in that area?

Speaker B: Not quite yet. So as a program evolves, our appreciation for what the entity, Cyber B that is privileged to sit in, the position we're sitting in, where our help might be needed. And one of the things that we've had to, um, you know, better understand is we have ISO requirements over ourselves, right? So CMMC early on was determined to be an ISO conforming program. So the CACO has to be, um, accredited under the ISO 1724 standard. C3PO is accredited under the ISO 1720 standard. We have to be recognized under the ISO 1711 standard, which is the standard for accreditation bodies. And accreditation bodies aren't supposed to be out there providing advice and guidance and assistance to small businesses. So in order to insulate that accreditation function, which is the primary reason we exist, we recently announced the creation of the Cyber Engagement form, or the Cyber ef. And that is what we are going to be really, um, Empowering and resourcing to get out there and not only spread the good news of the CMMC gospel, but to try to provide more assistance, more help. Especially not um, just for small businesses, but for MSPs. Because as I said, I think they are kind of an underserved part of the CMMC equation. And it's not something that the AB proper can do for ISO impartiality reasons and proprietary reasons. But the Sabre EF was really formed among other things to do that, to build a marketplace where MSPs that meet certain requirements can be listed, where MSPs, uh, customer, um, responsibility matrices, uh, could be validated. So there's some pilot programs within the Pentagon that I think will be kind of transferred to us in terms of helping MSPs to be able to have better confidence about where they sit and that they don't have to, you know, repeat the same process over and over again. Um, because they've got different clients who have different CTPOs assessing them. Right. So we're trying to figure out how do we reduce that burden. Right. And still, and still have the trust and confidence that if an MSP is really an integral part of that, of that running that network, that we're not disincentivizing MSPs from being a part of the CMMC equation.

Speaker C: I'm so glad you brought that up. Uh, because one of the challenges that we've run into is as an msp and we ran into it like we got hit with a two by four across the forehead with this one. Kaylee's laughing her butt off right now. Like when we were coming in for a landing just for our level two, the uh, 32 CFR hadn't come out. We weren't 100% sure how security protection data was going to be handled. So we had to play it safe. And a lot of times when we're working with our clients we have to play it more safe about uh, let's just take MFA for example. Some organizations feel that hello for Business, you know, doing the little pin with hello for Business is acceptable for mfa. Some assessors feel that way. Some assessors are like heck to the no, that's not acceptable either. You need to go with something like Duo. And the problem for us is we've got to navigate our clients through those waters and if they didn't have to use Duo, it would be cheaper for them.

Speaker B: Mhm.

Speaker C: But we also, if we went with like say let's just go with Windows for hello and they pick a C3PO that does not agree with that perspective, they just failed the assessment and I would have to object. And now it's costly again. So it's like this juxtaposition, this problem that we find ourselves in. Is that new program going to help with defining those types of things so that organizations like us can feel more comfortable about saying, well, in the body it says that hello for business is acceptable. Is that where that's going to kind of go to where we can start having almost like a. Where the case law that we can kind of sort of go back to, to kind of say see this was acceptable. Is that how that's going to possibly be?

Speaker B: It is, Bob. We call it the cmmc, uh, Body of Knowledge and uh, or be okay. And that's something that the cyber EF will kind of bring to life and maintain and curate the process by which. What goes in there and how is that validated? I think it'll be a combination between the A, B and R equities in terms of accreditation, uh, consistency, the DoD, you know, both the PMO and the DIBCAC who have equities in these types of questions and even other groups like the MSP Collective, the CMMC Industry Standards Council, other. There are other groups out there that are, you know, mostly, you know, not in, not private companies, um, but you know, the groups that have formed. We've got a C3 advisory council and coming up a way where if we're putting. Because your point is spot on. You look at NIST 800171 rev. 2110 things you got, you know, 110 research, security requirements, but 320 things you got to do or things that are going to be looked at. There's more than one way that's going to cast cat. But how many ways are there to skin a cat? How many legitimate ways are there to skin a cat? How do I find that? And that's what's missing. And that's what I think again what I think a uh, year into it now of Level 2 certifications being conducted, we realize that we can't just rely on 32 CFR and Nisihead 171 and the CAP. We need a place that is more not a living diet but a kind of a contemporaneous source of not truth but you know, best practice, accepted practice and enough C3POs say yep, I think that meets requirements and the DIBCAC agrees. Well then we'll put it in there. You know, that's exciting.

Speaker C: That is so exciting.

Speaker B: So we're working towards that. Actively, I don't have a timeframe from you, but very encouraging, uh, meetings with uh, Dow in May. And uh, we are driving towards that.

Speaker C: So, um, one of the main goals just to shift gears here of the Cyber AB is to protect the ecosystem. And it can be challenging for organizations that are like, look, our goal is to try to help save these companies money and they're going to try to pick options and do things, but they may not be in line with those and it might be from good spirits or perspective that they go to do that. So I could see where it could be very challenging for the Cyber AB to kind of regulate and work with uh, MSPs, C3POs that aren't handling things correctly. Can you talk to how you guys have stepped into the space, maybe use some examples of how you guys have had to do that, what your plans are around to continue to do it? Because I think as organizations go to step into this space, they want to know that if they're doing it right and it's going to cost them more, that they're not going to get undersold and undercut by someone else who does not have the same ethics that they have in their approach.

Speaker B: Yeah.

Speaker A: What wanted posters have you put up?

Speaker B: Well, you know, we're close to that because we came across just last week, uh, a bogus level 2 certificate that a non C3PO generated, taking a valid UID from another C3PO and some poor DIB company was uh, snookered into. I won't get into that. So that might be the first wanted poster. We're, that's a relatively new case we're working on. Uh, it's a terribly important question, Bobby. It's again why we exist one of those three pillars or two of the three. And I would say, I would answer initially that that way there are two types of infractions that we have the authorities to police as well as adjudicate. So we're the, we're the detective and the judge and jury in a lot of this. Some of those are technical infractions. Right. So to make sure that if uh, a C3PO is allowing certain, uh, approaches or technologies or services, making sure that they in fact meet uh, the security requirements of the NIST standard. And to your point, companies want to find, MSP is going to want to find efficiencies, the osc. So we have to be ready to evolve as people come up with innovative ways to meet requirements. And then there is the ethics piece. Are, uh, people cutting corners in terms of what they know is either the letter or spirit of the rule. Now, in some cases, it's like you pour water, water's always going to find the quickest path to freedom. I think C3PS now that it's game on, and there are business competition pressures there that some OSCs are putting in bake offs who can do it for the cheapest. And C3PO is like, wow, if I have to, uh, bid this, how am I going to do it for that? Right. That's what we really have to look closely. We can't have, certainly can't have certificate mills. But we also need to make sure that MSPs aren't getting too chummy with C3POs where there's, you know, they could certainly a C3PO who is not allowed to help implement or prepare if they want to certify that defense contractor, but they can refer them to an MSP or an RPO who could help them. And there's a difference between referring and endorsing. Right. So we're on the lookout for joint marketing endorsements, you know, a little too close for comfort. Uh, C3POs need to keep their distance, uh, from MSPs, RPOs, MSSPs, CSPs, if they intend to certify the clients of those entities. Right. If they don't and they just go, then that's what they should be doing. Right. Identifying potential conflict than mitigating or avoiding, depending on what's going on. I think nothing will undermine. I'll just finish. I think nothing will undermine the legitimacy of the program quicker if we don't do our job well in this area. Yeah.

Speaker C: How could people report that to you?

Speaker B: Complaints@cyberab.org as simple as that. We will, we can maintain your anonymity. And even if you don't have hard evidence, if you have concerns, you know, we can, we've got some wide authorities. These are administrative authorities, Right. We don't, we don't have the power of the government behind us and we can only take action against, uh, those that are in the ecosystem. Right. So if there is a company that's not an RPO, an RP or an instructor, an assessor or C3PO that we can, we will contact them. We will, whether it's irresponsible marketing or something. But clearly those who are under our authorities, we have everything from a kind verbal reminder, you shouldn't do that, to a written, you know, letter of instruction, letter of reprimand, and ultimately suspending or completely removing their credentials. And they're out of the program.

Speaker A: Yeah, yeah, I know we're getting to the very end, but I did want to ask just one quick thing before we close today, which is something that has happened more recently, and I just wanted to get just a short, you know, story or perspective from you, Keiko, and what has occurred in the ecosystem recently and what CCPs and CCAs can look forward to in the future. Just because I know, again, this is such an important part. I mean, I cannot stress enough. I encourage people to take the CCP course. Like it is breath that I breathe. You know, uh, I just went through it and passed my ccp and, um, it was really eye opening to go through. So I greatly encourage anybody that I'm talking to to go through this. But if you want to give just a brief description of. Because I know ISACA just recently took over and is going to be running things as well. So did you want to share just a little bit about that for. For people that are going into the ecosystem right now before we close?

Speaker B: Absolutely. Kaylie and I'll go back. We started the discussion about some of the history. I'll go back to that history. Because initially, when this was all started, the Pentagon wanted the AB to do everything, to do the accreditation and to train and certify the assessors and the CCPs. And then once they realized, well, we really should put this under ISO. Okay, uh, well, now we can't have the AB do everything. And so the plan was always to find a good home for the Caicos. But back in 2021, when the program was paused for six months, that went into the easel rulemaking, there was really no takers until the program actually was.

Speaker A: Somebody wasn't signing up for that yet.

Speaker B: Yeah. But, um, we had conversations with ISACA along the way, and we knew that given all the kind of challenges we were facing financially, that once the rulemaking was finished, we would not be in a position to resource the Keiko appropriately. Because you think about it, CMMC is a global program. We've got to start CREAT exams in foreign languages. Right. And then that has to be done under the ISO 1724. You can't just do a translation. You got to go back through the accreditation process. Ah. And that's an expense. And we didn't have the international network. I mean, we didn't have an explicit responsibility to recruit assessors. But it was certainly in our and everyone else's interest, as you rightly point out, Bobby, that there be more assessors. And so having a global reach Having established credibility as a, as a personnel certification entity in the IT and cybersecurity space was big. And so to us it was, or to me, I should say it was a no brainer. Thankfully, my board saw that as well and they're going to make some changes. Um, and so I know some of the changes have gotten people's attention or maybe don't sit well with them, but they certainly have the best interest of the program for the long term and I'm excited that they're part of the CMMC community.

Speaker C: Is ISACA going to be the only organization that can create material or can. Because you have the LPPs that could create their own content and it had to go through the catm and then it went through the dod. Can that, is that still allowed to happen or is it only going to

Speaker B: be the Keiko can create that's being phased out. So one of the things early on that model of decentralized publishing sounded great. Have licensed publishing partners create their material and then have it, you know, kind of QA'd at the AB and PMO level. But that's really runs against 1724. You want consistency in training materials that go to professional examinations. So they phasing out the publishing partners, they've all been informed. And um, starting later this year it'll be uh, isaca, the Keiko will be the only generator of CMMC authorized training material.

Speaker C: Got it.

Speaker B: Okay.

Speaker A: Well, I could, I could truly just keep asking you questions, but I know you actually have a job to do. That's sort of why we also have you here. So we do encourage you to keep doing that job, you know, um, because I don't know what would happen if you didn't. But I do want to say thank you. Thank you so much for taking the time to be on a little itty bitty podcast episode like us. Um, it's been wonderful having you, so

Speaker B: thank you so much, uh, love, never been happy back at the appropriate time because, you know, this program is moving. Things are going to be changing in terms of a lot of the things we talked about and especially once we have something more tangible in terms of helping the MSP community finding um, appropriate place in the marketplace so they can be more visible. The ones that, you know, that are invested in cmmc. I'd be excited to talk about that. Bring Mike Snyder along with me. So that'd uh, be great. I hope I'm invited back in months

Speaker C: to come open mic for you, you and Mike. Yeah, absolutely.

Speaker A: Yes, we would love that. Yeah. Well, guys, I hope you enjoyed today's episode. Um, since we cornered Matt Travis for you all in this little itty bitty corner of the CMMC space. Um, stay tuned Again every Thursday we post another episode so follow us and, and keep track of what we're doing. Um, and also make sure to stay tuned for um, you know Cyber AB's website has amazing material and also um, all of the things that you need to know about the ecosystem, what you need to look at resources there. So, so stay tuned. Um, on, on their po they post

Speaker C: the town halls on there too.

Speaker B: Thank you.

Speaker A: Yes, those are great. What I'll do is I' that down below too so they can check that out easily. Um, as well as the website itself. Um, and yeah we hope you guys enjoyed today's episode but as always guys, continue to keep on climbing. We'll see you. Bye bye.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The four phases of a CMMC assessmentTrust Issues · on CUI (Controlled Unclassified Information)84 / 100
  • The CMMC Reality Check: Gap Assessments, Documentation Overload & Why 30-Day Compliance Claims Are a Red FlagCMMC Compliance Guide · on CUI (Controlled Unclassified Information)80 / 100
  • A Perfect SPRS Score Turned Into a $507K SettlementSum IT Up: CMMC News Roundup · on DibCAC64 / 100
  • 30 - Teaching AI to Protect CUICyber Compliance & Beyond · on CUI (Controlled Unclassified Information)58 / 100

More from Climbing Mount CMMC

All episodes →
  • How To Pass CMMC The First Time
  • How To Master the CCP/CCA Courses
  • A Deep Dive into Rev 3: Incident Response (feat. Adam Evans)
  • What Qualifies As a "Significant Change" in CMMC?
  • What is CMMC Inheritance and How Do I Apply It? (feat. Adam Evans)
Explore the best B2B Ops podcasts →
All Climbing Mount CMMC episodes →